- remote_dump-rs: dumping CRC32 PEB modules and exports related to FFmodule HTB challenge.
- pic-shellcode: Position Independent Shellcode for shell-handler (coming soon).
- Stager
- Stage
- Common TCP Reverse Shell
- portscan-rs: simple portscanning subnet/CIDR.
- mini-enum: mini version of EFEW.
- keyed: encrypting files in HC-256, RC4, and xor cipher
0xAA. - reflect: packing executable with Dynamic Resolve API via Hash, Manual Mapping (Reflective PE Loader), & RC4 encryption (upx-like)
- exec-assembly
- Dynamic Resolve API (PoC: Shellcode Execution) – succeed.
-
ntdll.dll -
kernel32.dll
-
- mini-grep implementation
- InvokeMethod(String, Object)
- AppLocker Settings
- Arp Tables
- Clipboard Monitor
- Copies file monitor
- Saving all files & texts into
C:\Windows\Temp\EFEW\Clip.CF_HDROPandC:\Windows\Temp\EFEW\Clip.CF_UNICODETEXT
- Cloud Credentials
- DNS Caches
- FileVersionInfo.GetVersionInfo(String)
- Local Recyclebin
- Microsoft Updates
- Scheduled Task
- TCP UDP Connections
- WIfi Dumping Example
- Logon Sessions
- Powershell History
- Windows Services
- Screen Screenshot
- Enumerates all HWND windows & states
- Manipulate window states
- After that, take a screenshot
- Procdump / Nanodump
- Winpspy
- Enumeration for Mocking Jay (RWX Sections in DLLs that already installed on the target)
- Enumeration for
ShellExecuteExW()in the target processes, reference taken from here - ETW Bypass
- Inline Execute
- runas
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|